Enterprise-grade security for projects where data is as important as delivery
Operational readiness programmes handle sensitive asset data, O&M documentation, and operator competency records across multiple organisations.
CxPlanner is built to enterprise data security compliance standards - GDPR-compliant by default, hosted on AWS EU, with SSO support, role-based access control, full audit logs, and penetration testing by a firm that also tests government systems. Built to clear procurement barriers, not create them.
Book a demo
Sensitive programme data handled without the right controls.
Enterprise procurement teams block good software for a reason. The security bar on safety-critical projects is not optional.
Asset and O&M data shared without access controls.
Critical infrastructure data moves between contractors and documentation teams: asset records, O&M manuals, spare parts strategies. It travels by email and shared drives, with no enterprise data security compliance in place. The owner has no record of who saw what.
Operator competency records not handled to GDPR standard.
Training records are personal data. When stored in project spreadsheets and shared drives, they are not handled to the standard required by GDPR and equivalent frameworks. GDPR commissioning software compliance cannot be an afterthought on a programme that crosses EU data boundaries.
No audit trail of who accessed programme data.
When data lives across multiple tools and shared drives, there is no reliable record of who accessed which documents, when, and what changed. For safety-critical facilities, this is a compliance exposure that surfaces at the worst possible time.
Enterprise data security compliance, backed by role-based access and a full audit trail.
CxPlanner is built to enterprise data security compliance standards from the ground up. GDPR-compliant by default. Hosted on AWS with EU or US data residency. Every access, change, and sign-off recorded and time-stamped automatically.
The platform can also run in your own dedicated VPC (Virtual Private Cloud) - a gov-cloud environment limited to your servers, database, and access. A standard Data Processing Agreement is ready to sign.
Access to programme data - asset records, O&M documentation, training records, gate sign-offs - is role-based and controlled. Each contributing organisation sees only the data relevant to their scope. The operational readiness platform audit trail is built throughout the programme - not reconstructed for a compliance review.
Here is how it works
Role-based access configured at programme start
Each contributing organisation is assigned access to the scope and data relevant to their role. Contractors see their own scope. The owner sees all scopes. No more than necessary.
GDPR-compliant handling of personal data
Operator training records and competency sign-offs are personal data. CxPlanner handles them to the standard required by GDPR commissioning frameworks - not stored in project spreadsheets.
Full audit trail maintained automatically
Every access, change, and sign-off across the enterprise data security compliance programme is recorded and time-stamped. Built throughout the programme - not compiled for a compliance review.
SSO connected to existing identity infrastructure
CxPlanner supports SSO via SAML, Azure AD, Google Workspace, and Okta - so access is controlled through the owner's existing identity framework.
3rd-party penetration testing
Penetration tested by retest.dk that also tests government systems.
What CxPlanner covers for security and compliance
Built to enterprise procurement standards - not added as a feature.
GDPR compliance built in, not configured per customer
GDPR commissioning software compliance built in - not configured per customer. Personal data including operator training records and competency sign-offs handled to the required standard. Standard DPA ready to sign.
EU or US data residency, both available now
Hosted on AWS EU with EU data residency as the default. AWS US hosting coming for North American customers. Custom hosting available for enterprise contracts where required.
Single sign-on through your existing identity provider
Single sign-on support via SAML, Azure AD, Google Workspace, and Okta. Access to the operational readiness platform controlled through the owner's existing identity infrastructure - no separate credential management.
Granular permissions per project, system, and document
Granular permissions per project, system, and document. Enterprise data security compliance enforced at the access level - each party sees what they need, nothing more.
Every change tracked, every user accountable
Every change tracked, every user accountable. Data encrypted in transit and at rest. Backup and disaster recovery policies in place. 3rd-party penetration testing by a firm that also tests government systems. Vendor security questionnaire response available as a downloadable PDF.
What changes when security is built in, not bolted on
Procurement barriers clear. Programme data protected. Audit trail ready when asked for.
The procurement review does not block a good decision.
IT security, procurement, and legal teams have a clear answer for every question - GDPR compliance, EU data residency, SSO support, audit logs, penetration testing. Enterprise data security compliance documentation is available before the review, not produced in response to it.
Sensitive asset data is protected throughout the programme.
Critical infrastructure asset data shared only with the people who need it, at the access level appropriate to their role. No uncontrolled sharing via email. The operational readiness platform enforces the controls from the first day of the programme.
The audit trail is ready when the regulator asks.
Every access, change, and sign-off is recorded automatically throughout the programme. When a compliance review or regulatory enquiry requires the full enterprise data security compliance record, it is already there.
See how CxPlanner meets your enterprise requirements
If your IT security or procurement team needs documentation before they can approve CxPlanner, we have it ready. Book a conversation and we will walk through enterprise data security compliance against your specific requirements.
Book a demoRequest security documentationCommon questions about security and compliance in CxPlanner
Is CxPlanner GDPR compliant for handling operator training records?
Yes. Operator training records and competency sign-offs are personal data. CxPlanner handles them to the standard required by GDPR commissioning software frameworks - stored securely, access-controlled, and auditable. Standard DPA available to sign.
Where is CxPlanner data hosted?
AWS EU with EU data residency as the default. AWS US hosting is available for North American customers.
Can we choose our own hosting location?
Yes. CxPlanner supports hosting in AU, CA, EU, or US, including your own dedicated VPC for enterprise contracts that require it.
Does CxPlanner support SSO?
Yes. CxPlanner supports single sign-on via SAML, Azure AD, Google Workspace, and Okta - so access to the operational readiness platform is controlled through the owner organisation's existing identity framework.